logo

Behind the scenes in the Expel SOC: Alert-to-fix in AWS

ID: 4289a190-2717-543d-8c64-37fbced05356

STIX ID: report--4289a190-2717-543d-8c64-37fbced05356

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2020-07-28

Date Updated: 2026-04-27

Author: Jon Hencinski; Anthony Randazzo; Sam Lipton; Lori Easterly

...
...

Over the July 4th weekend Expel’s SOC detected that a compromised AWS root access key was used to create SSH key pairs, spin up ten c5.4xlarge EC2 instances, and connect to a Monero mining pool; the team used CloudTrail and GuardDuty signals plus automated tooling to triage, escalate to the Global Response Team, and contain the incident within 37 minutes by removing the stolen key, terminating instances, and deleting malicious security groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.